Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2019-02-15 CVE-2013-2565 Path Traversal vulnerability in Mambo-Foundation Mambo CMS 4.6.5
A vulnerability in Mambo CMS v4.6.5 where the scripts thumbs.php, editorFrame.php, editor.php, images.php, manager.php discloses the root path of the webserver.
network
low complexity
mambo-foundation CWE-22
5.3
2019-02-13 CVE-2019-5910 Path Traversal vulnerability in Housegate House Gate 1.7.8
Directory traversal vulnerability in HOUSE GATE App for iOS 1.7.8 and earlier allows remote attackers to read arbitrary files via unspecified vectors.
network
low complexity
housegate CWE-22
7.5
2019-02-10 CVE-2018-20769 Path Traversal vulnerability in Xerox products
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000.
network
low complexity
xerox CWE-22
7.5
2019-02-09 CVE-2019-7678 Path Traversal vulnerability in Enphase Envoy
A directory traversal vulnerability was discovered in Enphase Envoy R3.*.* via images/, include/, include/js, or include/css on TCP port 8888.
network
low complexity
enphase CWE-22
critical
9.8
2019-02-05 CVE-2018-20251 Path Traversal vulnerability in Rarlab Winrar
In WinRAR versions prior to and including 5.61, there is path traversal vulnerability when crafting the filename field of the ACE format.
local
low complexity
rarlab CWE-22
5.5
2019-02-05 CVE-2018-20250 Path Traversal vulnerability in Rarlab Winrar
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll).
local
low complexity
rarlab CWE-22
7.8
2019-02-05 CVE-2018-18990 Path Traversal vulnerability in Lcds Laquis Scada 4.1/4.1.0.3391/4.1.0.3870
LCDS Laquis SCADA prior to version 4.1.0.4150 allows a user-supplied path in file operations prior to proper validation.
network
low complexity
lcds CWE-22
5.3
2019-02-05 CVE-2019-7403 Path Traversal vulnerability in PHPmywind 5.5
An issue was discovered in PHPMyWind 5.5.
network
low complexity
phpmywind CWE-22
4.9
2019-02-04 CVE-2019-7387 Path Traversal vulnerability in Systrome products
A local file inclusion vulnerability exists in the web interface of Systrome Cumilon ISG-600C, ISG-600H, and ISG-800W 1.1-R2.1_TRUNK-20180914.bin devices.
network
low complexity
systrome CWE-22
6.5
2019-02-04 CVE-2019-1000009 Path Traversal vulnerability in Helm Chartmuseum
Helm ChartMuseum version >=0.1.0 and < 0.8.1 contains a CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in HTTP API to save charts that can result in a specially crafted chart could be uploaded and saved outside the intended location.
network
low complexity
helm CWE-22
6.5